[MAVEN:GHSA-JM7R-4PG6-GF26] Esoteric YamlBeans Unsafe Deserialization vulnerability

Severity High
Affected Packages 1
CVEs 1

An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

Package Affected Version
pkg:maven/com.esotericsoftware.yamlbeans/yamlbeans <= 1.15
ID
MAVEN:GHSA-JM7R-4PG6-GF26
Severity
high
URL
https://github.com/advisories/GHSA-jm7r-4pg6-gf26
Published
2023-08-25T21:30:47
(13 months ago)
Modified
2023-11-08T05:00:54
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.esotericsoftware.yamlbeans/yamlbeans com.esotericsoftware.yamlbeans yamlbeans <= 1.15
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...